Working Group
Regulatory Analysis and Compliance Engineering
Developing machine-readable mappings, automation tools, and methodologies to align cybersecurity controls with evolving regulations.
- Develops best practices for regulatory mapping and compliance gap analysis.
- Creates machine-readable formats for regulatory frameworks.
- Establishes methodologies for analyzing and mapping regulatory requirements to control objectives.
- Defines logical rules for regulatory interpretation and cross-framework mapping.
- Identifies relationships between regulatory controls (e.g., One-to-One, One-to-Many, Many-to-Many mappings).
- Develops protocols for engaging with regulators and standards bodies to validate and approve mappings.
- Design regulatory analysis tooling leveraging AI/ML for automating compliance interpretation.
- Produces a framework for aligning regulatory requirements with continuous control monitoring and auditing.
Working Group Leadership

Larry Hughes

Daniele Catteddu
Chief Technology Officer, CSA
Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Andy Ruth
Content Developer, CSA
Publications in Review | Open Until |
---|---|
Agentic AI Red Teaming Guide | Apr 27, 2025 |
AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) | Apr 28, 2025 |
Secure Agentic System Design - A Trait-Based Approach | May 15, 2025 |
Managing Privileged Access in a Cloud-First World | May 23, 2025 |
Who can join?
Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.
What is the time commitment?
The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.
Open Peer Reviews
Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.